Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-68q5-78xp-cwwc

Опубликовано: 25 нояб. 2025
Источник: github
Github: Прошло ревью
CVSS3: 3.3

Описание

Contao is vulnerable to cross-site scripting in templates

Impact

It is possible to inject code into the template output that will be executed in the browser in the front end and back end.

Patches

Update to Contao 4.13.57, 5.3.42 or 5.6.5.

Workarounds

Do not use the affected templates or patch them manually.

Refsources

https://contao.org/en/security-advisories/cross-site-scripting-in-templates

Пакеты

Наименование

contao/core-bundle

composer
Затронутые версииВерсия исправления

>= 4.0.0, < 4.13.57

4.13.57

Наименование

contao/core-bundle

composer
Затронутые версииВерсия исправления

>= 5.0.0-RC1, < 5.3.42

5.3.42

Наименование

contao/core-bundle

composer
Затронутые версииВерсия исправления

>= 5.4.0-RC1, < 5.6.5

5.6.5

EPSS

Процентиль: 8%
0.00028
Низкий

3.3 Low

CVSS3

Дефекты

CWE-79
CWE-87

Связанные уязвимости

CVSS3: 3.3
nvd
2 месяца назад

Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, it is possible to inject code into the template output that will be executed in the browser in the front end and back end. This issue has been patched in versions 4.13.57, 5.3.42, and 5.6.5. A workaround for this issue involves not using the affected templates or patch them manually.

EPSS

Процентиль: 8%
0.00028
Низкий

3.3 Low

CVSS3

Дефекты

CWE-79
CWE-87